<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 2530 switches will not allow ssh or https in HPE Aruba Networking &amp; ProVision-based</title>
    <link>https://community.hpe.com/t5/hpe-aruba-networking-provision/2530-switches-will-not-allow-ssh-or-https/m-p/6847012#M9727</link>
    <description>&lt;P&gt;&amp;nbsp;So this switch is connected to two other 2530's on ports 21 and 23. Port 24 was to an additional netgear switch that only required vlan 2, so that was untagged. The tagged vlans on 24 can be ignored, so I must remove those.&lt;/P&gt;&lt;P&gt;So this switch is not directly connected to the core, so kind of bad example. But one that is which is in the same position, has on its uplink at the core, untagged vl 2, tagged vl 3-6.&lt;/P&gt;&lt;P&gt;vlan 1&lt;BR /&gt;&amp;nbsp;&amp;nbsp; name "DEFAULT_VLAN"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; no untagged 1-48&lt;BR /&gt;&amp;nbsp;&amp;nbsp; untagged 49-52&lt;BR /&gt;&amp;nbsp;&amp;nbsp; no ip address&lt;BR /&gt;&amp;nbsp;&amp;nbsp; exit&lt;BR /&gt;vlan 2&lt;BR /&gt;&amp;nbsp;&amp;nbsp; name "wired"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; untagged 1-48&lt;BR /&gt;&amp;nbsp;&amp;nbsp; no ip address&lt;BR /&gt;&amp;nbsp;&amp;nbsp; exit&lt;BR /&gt;vlan 3&lt;BR /&gt;&amp;nbsp;&amp;nbsp; name "private-wifi"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; tagged 48&lt;BR /&gt;&amp;nbsp;&amp;nbsp; no ip address&lt;BR /&gt;&amp;nbsp;&amp;nbsp; exit&lt;BR /&gt;vlan 4&lt;BR /&gt;&amp;nbsp;&amp;nbsp; name "public-wifi"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; tagged 48&lt;BR /&gt;&amp;nbsp;&amp;nbsp; no ip address&lt;BR /&gt;&amp;nbsp;&amp;nbsp; exit&lt;BR /&gt;vlan 5&lt;BR /&gt;&amp;nbsp;&amp;nbsp; name "community"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; tagged 48&lt;BR /&gt;&amp;nbsp;&amp;nbsp; no ip address&lt;BR /&gt;&amp;nbsp;&amp;nbsp; exit&lt;BR /&gt;vlan 6&lt;BR /&gt;&amp;nbsp;&amp;nbsp; name "servers"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; tagged 48&lt;BR /&gt;&amp;nbsp;&amp;nbsp; ip address&amp;nbsp;x.x.x.x&lt;BR /&gt;&amp;nbsp;&amp;nbsp; exit&lt;/P&gt;</description>
    <pubDate>Fri, 01 Apr 2016 08:17:42 GMT</pubDate>
    <dc:creator>karls</dc:creator>
    <dc:date>2016-04-01T08:17:42Z</dc:date>
    <item>
      <title>2530 switches will not allow ssh or https</title>
      <link>https://community.hpe.com/t5/hpe-aruba-networking-provision/2530-switches-will-not-allow-ssh-or-https/m-p/6846910#M9724</link>
      <description>&lt;P&gt;Right where to start, I can not for love nor money get 26 2530s switches to allow ssh or https access. The switches will accept the config and an example of one is provided.&lt;/P&gt;&lt;P&gt;; J9854A Configuration Editor; Created on release #YA.15.16.0006&lt;BR /&gt;; Ver #06:04.9c.63.ff.37.27:12&lt;BR /&gt;hostname "castle-comms"&lt;BR /&gt;timesync sntp&lt;BR /&gt;sntp unicast&lt;BR /&gt;sntp server priority 1 x.x.x.x&lt;BR /&gt;no telnet-server&lt;BR /&gt;no web-management&lt;BR /&gt;web-management ssl&lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 x.x.x.x&lt;BR /&gt;interface 21&lt;BR /&gt;&amp;nbsp;&amp;nbsp; name "link-to-castle-comms-2nd-switch"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; exit&lt;BR /&gt;interface 23&lt;BR /&gt;&amp;nbsp;&amp;nbsp; name "link-to-castle-prefab"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; exit&lt;BR /&gt;interface 24&lt;BR /&gt;&amp;nbsp;&amp;nbsp; name "ground-castle-nurse"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; exit&lt;BR /&gt;vlan 1&lt;BR /&gt;&amp;nbsp;&amp;nbsp; name "DEFAULT_VLAN"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; no untagged 1-24&lt;BR /&gt;&amp;nbsp;&amp;nbsp; untagged 25-26&lt;BR /&gt;&amp;nbsp;&amp;nbsp; no ip address&lt;BR /&gt;&amp;nbsp;&amp;nbsp; exit&lt;BR /&gt;vlan 2&lt;BR /&gt;&amp;nbsp;&amp;nbsp; name "wired"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; untagged 1-12,24&lt;BR /&gt;&amp;nbsp;&amp;nbsp; tagged 21,23&lt;BR /&gt;&amp;nbsp;&amp;nbsp; no ip address&lt;BR /&gt;&amp;nbsp;&amp;nbsp; exit&lt;BR /&gt;vlan 3&lt;BR /&gt;&amp;nbsp;&amp;nbsp; name "private-wifi"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; untagged 13-20,22&lt;BR /&gt;&amp;nbsp;&amp;nbsp; tagged 21,23-24&lt;BR /&gt;&amp;nbsp;&amp;nbsp; no ip address&lt;BR /&gt;&amp;nbsp;&amp;nbsp; exit&lt;BR /&gt;vlan 4&lt;BR /&gt;&amp;nbsp;&amp;nbsp; name "public-wifi"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; tagged 21,23-24&lt;BR /&gt;&amp;nbsp;&amp;nbsp; no ip address&lt;BR /&gt;&amp;nbsp;&amp;nbsp; exit&lt;BR /&gt;vlan 5&lt;BR /&gt;&amp;nbsp;&amp;nbsp; name "community"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; tagged 21,23-24&lt;BR /&gt;&amp;nbsp;&amp;nbsp; no ip address&lt;BR /&gt;&amp;nbsp;&amp;nbsp; exit&lt;BR /&gt;vlan 6&lt;BR /&gt;&amp;nbsp;&amp;nbsp; name "servers"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; tagged 21,23-24&lt;BR /&gt;&amp;nbsp;&amp;nbsp; ip address x.x.x.x x.x.x.x&lt;BR /&gt;&amp;nbsp;&amp;nbsp; exit&lt;BR /&gt;no tftp server&lt;BR /&gt;no dhcp config-file-update&lt;BR /&gt;no dhcp image-file-update&lt;BR /&gt;no dhcp tr69-acs-url&lt;BR /&gt;password manager&lt;BR /&gt;password operator&lt;/P&gt;&lt;P&gt;I can see the certs after I create them but I cant&amp;nbsp;not access the switches via ssh or https. To add confusion to the matter, I can not ping the switches either once they are on the network.&lt;/P&gt;&lt;P&gt;The core switch is a netgear (i know, but this is being replaced with a 5500 once I resolve these issues), yet the core is working without issue.&lt;/P&gt;&lt;P&gt;And lastly, I can not at this time upgrade the firmware as the tftp steps is providing an error. Cant recall at this time what it is.&lt;/P&gt;&lt;P&gt;The rest of the network is made up of 1920s switches which are working fine, ssh, https all good.&lt;/P&gt;&lt;P&gt;Steps taken, rebuild the switches, deleted crypto keys for ssh and pki. Reconfig those but still no joy. Also rebuild the switches offline and provided myself with a static IP and still no joy.&lt;/P&gt;&lt;P&gt;Apart from launch these switches into the sea, I am questioning either fireware or hardware failure.&lt;/P&gt;&lt;P&gt;Has anyone seen this before or any tips on next steps.&lt;/P&gt;&lt;P&gt;Thanks....&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2016 20:15:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-aruba-networking-provision/2530-switches-will-not-allow-ssh-or-https/m-p/6846910#M9724</guid>
      <dc:creator>karls</dc:creator>
      <dc:date>2016-03-31T20:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: 2530 switches will not allow ssh or https</title>
      <link>https://community.hpe.com/t5/hpe-aruba-networking-provision/2530-switches-will-not-allow-ssh-or-https/m-p/6846928#M9725</link>
      <description>&lt;P&gt;I have a different 2530, a J9774a, and on mine an all other recent provision based switches, SSH is enabled by default. I am running YA.16.01 software.&lt;/P&gt;&lt;P&gt;I am concerned that you can't even ping your switch. That makes me think that your VLAN configuration isn't quite right. I assume that ports 23 and 24 connect to the rest of your network and that you want to manage the switch in vlan 6. But ports 23 and 24 are configured slightly differently. Port 23 doesn't carry any untagged traffic and port 24 carries VLAN 2 untagged. Is that intentional?&lt;/P&gt;&lt;P&gt;I think there are two options to figure this out.&lt;/P&gt;&lt;P&gt;1. Can you share the config of the port that this switch connects to on the netgear? And let us know which port on the 2530 it is connecting to.&lt;/P&gt;&lt;P&gt;2. Or you can reset to factory defaults and connect the switch to a port on the netgear that is untagged with DHCP. The 2530 will get a DHCP address and then you can validate connectivity and update the software before reconfiguring for your network.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2016 21:27:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-aruba-networking-provision/2530-switches-will-not-allow-ssh-or-https/m-p/6846928#M9725</guid>
      <dc:creator>EricAtHP</dc:creator>
      <dc:date>2016-03-31T21:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: 2530 switches will not allow ssh or https</title>
      <link>https://community.hpe.com/t5/hpe-aruba-networking-provision/2530-switches-will-not-allow-ssh-or-https/m-p/6847012#M9727</link>
      <description>&lt;P&gt;&amp;nbsp;So this switch is connected to two other 2530's on ports 21 and 23. Port 24 was to an additional netgear switch that only required vlan 2, so that was untagged. The tagged vlans on 24 can be ignored, so I must remove those.&lt;/P&gt;&lt;P&gt;So this switch is not directly connected to the core, so kind of bad example. But one that is which is in the same position, has on its uplink at the core, untagged vl 2, tagged vl 3-6.&lt;/P&gt;&lt;P&gt;vlan 1&lt;BR /&gt;&amp;nbsp;&amp;nbsp; name "DEFAULT_VLAN"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; no untagged 1-48&lt;BR /&gt;&amp;nbsp;&amp;nbsp; untagged 49-52&lt;BR /&gt;&amp;nbsp;&amp;nbsp; no ip address&lt;BR /&gt;&amp;nbsp;&amp;nbsp; exit&lt;BR /&gt;vlan 2&lt;BR /&gt;&amp;nbsp;&amp;nbsp; name "wired"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; untagged 1-48&lt;BR /&gt;&amp;nbsp;&amp;nbsp; no ip address&lt;BR /&gt;&amp;nbsp;&amp;nbsp; exit&lt;BR /&gt;vlan 3&lt;BR /&gt;&amp;nbsp;&amp;nbsp; name "private-wifi"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; tagged 48&lt;BR /&gt;&amp;nbsp;&amp;nbsp; no ip address&lt;BR /&gt;&amp;nbsp;&amp;nbsp; exit&lt;BR /&gt;vlan 4&lt;BR /&gt;&amp;nbsp;&amp;nbsp; name "public-wifi"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; tagged 48&lt;BR /&gt;&amp;nbsp;&amp;nbsp; no ip address&lt;BR /&gt;&amp;nbsp;&amp;nbsp; exit&lt;BR /&gt;vlan 5&lt;BR /&gt;&amp;nbsp;&amp;nbsp; name "community"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; tagged 48&lt;BR /&gt;&amp;nbsp;&amp;nbsp; no ip address&lt;BR /&gt;&amp;nbsp;&amp;nbsp; exit&lt;BR /&gt;vlan 6&lt;BR /&gt;&amp;nbsp;&amp;nbsp; name "servers"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; tagged 48&lt;BR /&gt;&amp;nbsp;&amp;nbsp; ip address&amp;nbsp;x.x.x.x&lt;BR /&gt;&amp;nbsp;&amp;nbsp; exit&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2016 08:17:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-aruba-networking-provision/2530-switches-will-not-allow-ssh-or-https/m-p/6847012#M9727</guid>
      <dc:creator>karls</dc:creator>
      <dc:date>2016-04-01T08:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: 2530 switches will not allow ssh or https</title>
      <link>https://community.hpe.com/t5/hpe-aruba-networking-provision/2530-switches-will-not-allow-ssh-or-https/m-p/6847014#M9728</link>
      <description>&lt;P&gt;Also forgot to say that the switches are bleeding their config, which I see was a fix in one of the firmware updates.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2016 08:49:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-aruba-networking-provision/2530-switches-will-not-allow-ssh-or-https/m-p/6847014#M9728</guid>
      <dc:creator>karls</dc:creator>
      <dc:date>2016-04-01T08:49:12Z</dc:date>
    </item>
    <item>
      <title>Re: 2530 switches will not allow ssh or https</title>
      <link>https://community.hpe.com/t5/hpe-aruba-networking-provision/2530-switches-will-not-allow-ssh-or-https/m-p/6847163#M9732</link>
      <description>&lt;P&gt;divide and conquer strategy:&lt;BR /&gt;just&amp;nbsp; to make a switch port untagged in vlan6 , hook up a PC and test from there.&amp;nbsp; No need to bother about certificates private key stuff if you can't even ping&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2016 17:26:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-aruba-networking-provision/2530-switches-will-not-allow-ssh-or-https/m-p/6847163#M9732</guid>
      <dc:creator>16again</dc:creator>
      <dc:date>2016-04-01T17:26:37Z</dc:date>
    </item>
  </channel>
</rss>

